Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <43f96a10-24af-423b-bb21-f2f4001f5ed9@thomas-ward.net>
Date: Mon, 21 Apr 2025 12:52:24 -0400
From: Thomas Ward <teward@...mas-ward.net>
To: oss-security@...ts.openwall.com
Subject: Re: 3 new CVE's in old branch of GNU mailman

On 2025-04-21 12:48, Valtteri Vuorikoski wrote:
>> Are these vulnerabilities due to modifications made by the vendor (cPanel LLC) to
>> their distributed version?
>>
>>   -Valtteri

Direct quoting the CVE:

> *Affected Software:* GNU Mailman 2.1.39 (bundled with cPanel/WHM)

I think that this would be a modified bundled version based on "Affected 
Software" specifically mentioning the GNU Mailman 2.1.39 that is 
specifically bundled with cPanel/WHM.

Especially if you can't reproduce it in pure MM 2.1.39.

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.